Home/Trust

The trust layer, shown.

Every claim on this site has receipts. Audit chain, GDPR posture, EU AI Act register, certifications, sub-processors — all in one place.

Certifications

Audited, signed, current.

Each certification below has a current report or attestation. We'll send the artifacts under NDA.

01

SOC 2

Type II · 2026-Q1

02

ISO 27001

Certified · BSI

03

GDPR

EU controller-of-record

04

EU AI Act

High-risk register live

05

HIPAA

BAA available

06

eIDAS

Qualified timestamps

The Audit Chain

Every event signed, linked, yours to verify.

Each transformation appends a SHA-256-signed entry. The root is anchored daily to a qualified eIDAS timestamp authority.

TSEVENTACTORHASHSTATUS
14:22:08ingest.csvsystema1c0f2…ok
14:22:09schema.detectsystemb3d8e1…ok
14:22:11dedupe.mergesystemc4f7a3…ok
14:22:14row.overridealex@hospital.fid5b9c2…review
14:22:17validate.runsysteme6c1d4…ok
14:22:18bundle.signsystemf7d3e5…ok
Compliance Posture

One row per regulator.

Where each regime fits in. Each entry has a contact at AVA Research who owns the controls behind it.

GDPR

Controller-of-record + DPA on request. Right-to-erasure cascades to derivatives. EU-only data residency by default.

EU AI Act

Annex III high-risk register live. Reviewer attribution and rationale on every automated decision. Public summary opt-in.

HIPAA

BAA available on Industry. Safe Harbor + Expert Determination engines. PHI access logged with reason-codes.

DORA

ICT third-party register pre-validated. Operational resilience tests quarterly. Incident reporting templates included.

SOC 2

Type II for Security and Availability. Report under NDA. Continuous monitoring + manual quarterly review.

ISO 27001

Certified by BSI. SoA on request. ISMS reviewed annually. Annex A controls mapped to internal policies.

Sub-processors

Who else touches the data.

Updated 2026-Q2. Subscribe to changes via the DPA addendum.

VENDORPURPOSECATEGORY
Fly.ioEU hosting (fra)Infra
NeonPostgres (eu-central-1)Database
Cloudflare R2Object storage (versioned)Storage
UpstashRedis (EU)Cache + queue
AnthropicLLM inference (Sonnet 4.6)AI
PostmarkTransactional emailEmail

Want the full trust pack?

DPA, SOC 2 Type II report, ISO 27001 certificate, sub-processor change feed. We send the bundle under NDA — usually same-day.